Skip to content

Software Supply Chain Attacks: Why “Trusted Software” Still Needs Scrutiny

Photo-real image showing a trusted digital supply chain with one subtle compromised element representing supply chain attacks.

Software supply chain attacks are becoming one of the hardest cyber threats for organisations to detect – and a recent incident involving Axios shows why.

In March, Google researchers revealed that suspected North Korean threat actors were behind a supply chain attack involving Axios, a widely used open‑source JavaScript library downloaded millions of times each week. By briefly compromising a trusted maintainer account, attackers were able to publish malicious versions of the software, temporarily turning a common developer tool into a vehicle for credential‑stealing malware that could provide ongoing access to affected systems.

Although the compromised versions were removed within hours, Google warned the incident could still have far‑reaching impacts, as malicious code introduced through software supply chains can persist long after the original issue is fixed.

What happened in the Axios supply chain attack?

Axios (the software library, not Axios Media) is a foundational component used to help applications communicate with systems and services. It’s embedded across a huge number of modern development and cloud environments.

In this attack, threat actors linked by Google to a North Korean group were able to:

  • Gain access to a maintainer account
  • Publish malicious versions of the Axios package
  • Introduce credential‑stealing malware across macOS, Windows and Linux systems

Security researchers estimate Axios is downloaded around 100 million times per week and is present in a large proportion of cloud and code environments, highlighting how quickly a software supply chain attack can spread.

Why this incident matters beyond the headlines

Supply chain attacks like this are particularly effective because they exploit trust.

Rather than breaking in directly, attackers insert themselves into tools and software that organisations already rely on. Once malicious code is embedded into an environment, it can operate quietly, often bypassing traditional security controls that assume known applications are safe by default.

Security researchers have pointed out that even short‑lived compromises can leave a long tail of risk, as vulnerable code may persist in internal systems, production workloads, or downstream customer environments long after the initial breach is addressed.

What this means for New Zealand organisations

For many NZ organisations – including those in government, healthcare, education and critical infrastructure – software supply chains are deeply interconnected. Open‑source components, third‑party platforms, and managed services are embedded across everyday operations.

This incident raises some uncomfortable but necessary questions:

  • How confident are you in what’s running inside your environment today?
  • Would you detect suspicious behaviour if it came from a trusted application?
  • How quickly could you respond if the issue didn’t start with a user click or obvious alert?

Reducing exposure to software supply chain attacks

While it’s impossible to eliminate supply chain risk entirely, organisations can reduce impact by improving visibility across their environments.

At Advantage, our Protect services focus on:

  • Continuous monitoring across endpoints, networks and cloud workloads
  • Detecting abnormal behaviour, not just known threats
  • Reducing attacker dwell time through early detection and response
  • Providing clear insight into what’s happening inside your environment

The lesson from the Axios incident is straightforward: Trust in software should always be paired with verification.

Software supply chain attacks don’t announce themselves – but with the right visibility and response capability, their impact can be limited.

Facebook
Twitter
LinkedIn

Related Posts

Ask ten business leaders what their AI governance strategy is and you’ll probably get ten very different answers. Find out where your organisation sits.
We often talk about “the cloud” as if business data simply disappears into the internet. In reality, cloud services depend on very physical foundations. At the heart of Advantage Cloud is our data centre.
When users complain that systems are slow, the immediate response is often to question the internet connection. But increasingly, organisations are discovering that the real bottleneck sits much closer to home – the firewall.